Advertisement

Coldcard Exploit Deepens With New Bitcoin Drain, Total Losses Near $114 Million

A fourth round of Bitcoin sweeps linked to the Coldcard wallet vulnerability started early Monday and remained active for several hours. Unlike the earlier waves, researchers say the latest transactions may still be reversible because they are sitting unconfirmed and can potentially be replaced.

Alex Thorn, head of firmwide research at Galaxy Research, identified the ongoing activity and said the attackers enabled Bitcoin’s replace-by-fee (RBF) feature. RBF allows an unconfirmed transaction to be replaced with a new transaction offering a higher fee. This means victims who spot their wallet address in the mempool — the pool of pending Bitcoin transactions — may have a limited opportunity to submit a higher-fee transaction and move their funds before the attacker’s transaction is confirmed.

The first wave of the attack began on July 30, draining 1,083 BTC from 1,196 addresses within approximately 41 minutes. Two more waves over the weekend increased the known losses to 1,367 BTC across 4,585 addresses.

The underlying issue dates back to a March 2021 Coldcard firmware release that unintentionally directed seed generation to a predictable software random number generator instead of the device’s hardware-based randomness system. This reduced the security of wallet seeds, allowing attackers to reconstruct private keys offline once they identified the affected range.

Coldcard creator Coinkite responded by releasing emergency firmware updates for all affected models. The company advised users who created seeds on vulnerable firmware versions to generate new wallets with fresh seeds and transfer their assets away from compromised addresses.

Thorn clarified that he had not received direct confirmation from victims and that his conclusions were based on transaction patterns and blockchain analysis. He chose to release the information quickly because some transactions had not yet been finalized and users still had a chance to react.

If the latest wave is confirmed, the total losses from the four attack rounds could reach around 1,816 BTC, valued at nearly $114 million, involving more than 5,200 addresses since July 30.

Thorn recommended that affected users immediately check their wallets, transfer remaining funds away from vulnerable devices, and increase transaction fees where possible to compete against the attacker’s pending transactions.

Blockchain analysis showed the latest activity occurred across blocks 960,778 to 960,792, with 218 transactions targeting 462 victim addresses. The attackers carried out around 14 sweeps per block, compared with only about 0.3 sweeps per block during the comparison period before the incident — approximately a 45-fold increase.

Researchers found that the affected coins were linked to wallets created after the vulnerable Coldcard firmware threshold, while the destination addresses were newly generated and had no previous transaction activity. Unlike the first two attack waves, which were easier to track because they used shared collection addresses, the latest transactions sent funds to separate addresses for individual victims.

The first three waves did not affect multisignature wallets, reinforcing the assessment that the vulnerability mainly impacted single-key wallet seeds. Analysts also identified six destination addresses with older activity, indicating that some receiving addresses were not newly created by the attacker.